Training Catalogue
WWISE
SPEAK TO A CONSULTANT

ISO/IEC 27001:2022 Information Security

ISO/IEC 27001:2022 Information Security

The ISO/IEC 27001:2022 information security, cybersecurity and privacy protection standard assists organisations and their respective interested parties (clients, shareholders, stakeholders, government, unions, etc.) by instilling confidence that they have controls in place to reduce the risk of a cyber-attack and information breaches.

The ISO/IEC 27001 standard provides a framework for implementing an Information Security Management System (ISMS) that drives information security management through all levels of the organisation. The ISMS’s core function is to ensure processes within the scope of the organisation are able to provide assurance that the confidentiality, integrity, and availability of their information is preserved.

What is ISO/IEC 27001:2022?

The ISO/IEC 27001:2022 ISMS standard is broken up into two sections of controls, namely:

  1. Management clauses: These ISO/IEC 27001 requirements guide the organisations processes into a structured information security management system by following a risk-based approach aligned to the statement of applicability and information bearing assets to protect the confidentiality, integrity, availability, and organistions objectives.
  2. Operational controls: These 93 controls are categorised as organisational (37), people (8), physical (14), or technological (34). The ISO/IEC 27001 Annex A controls provide guidance on specific measures that must be taken to protect the organisation against information security threats.

The standard is defined in accordance with the Plan-Do-Check-Act cycle, as well as risk-and process-based methodologies. The ISO 27001 standard incorporates a broad range of information and technology security practices from more than 60 supporting guideline standards, including guidance on cloud security, cybersecurity, incident management, and network security. The standard also requires that the and are complied with.

The ISMS consists of a risk-based management system that mitigates vulnerabilities and threats with relevant controls such as policies, processes, procedures, work instructions, applications, systems, tools, associated logs and records needed to effectively capture how the organisation adheres to its objectives and targets aligned to its statement of applicability. The focus is to preserve the confidentiality, integrity, and availability of information amongst all relevant interested parties.

Some of the key controls in the ISO 27001 standard include physical and digital access control, network security and effective utilisation of firewalls, encryption methods, anti-virus , patch management, incident management, vulnerability management, backup management, business continuity and disaster recovery plans, and asset management. To achieve certification in this standard, your organisation must demonstrate the effective implementation of these controls, with evidence, as well as continual improvement of security practices.

 

A. Management Controls

Description Control Total
Clause 4 Context of the Organisation 9
Clause 5 Leadership 18
Clause 6 Planning 40
Clause 7 Support 24
Clause 8 Operation 8
Clause 9 Performance Evaluation 30
Clause 10 Improvement 13
ISMS CONTROL POINTS TOTAL 142

B. Operational Controls

Description Control Total
A 5 Organisational Controls 37
A 6 People Controls 8
A 7 Physical Controls 14
A 8 Technological Controls 34
Annex. A CONTROL POINTS TOTAL 93

Total Control Points

Total Controls Points: 235
Why does an Organisation need ISO/IEC 27001:2022?

As technology advances rapidly, data and information have become increasingly valuable to organisations. To protect the confidentiality, integrity, and availability of information, any organisation that handles sensitive internal and external information must align with international best practices. ISO/IEC 27001:2022 is an internationally recognised best practice standard that organisations can use to demonstrate that their protection against information security threats is on par with the best organisations in the world. ISO 27001 implementation helps promote a risk and security awareness culture and assists with managing security incidents, mitigating risks, and financial losses. The standard also provides organisations with the methodology for complying with the increasing legal requirements related to information security.

The recent boom in AI technology marks a milestone in the rate of technological advancement. AI tools video and voice deep fake technology are increasingly being used by hackers to gain access to victim organisations’ information. The updated ISO/IEC 27001:2022 standard takes AI technology into account to ensure that organisations are protected against the latest attack methods. ISO/IEC 42001:2023 Artificial Intelligence Management System (AIMS) can also be considered as an extension to ISO/IEC 27001:2022.

What are the Benefits of Implementing ISO/IEC 27001:2022?

Benefits include, but are not limited to:

  • Standardising processes within your organisation to ensure expected results are achieved consistently.
  • Safeguarding that sensitive information is protected from unauthorised access.
  • Ensuring that information is not corrupted or changed without appropriate control.
  • Guaranteeing that information is available where and when needed.
  • Implementing effective controls to protect the organisation against even the most advanced cyber attacks.
  • Preparing your organisation to respond effectively to potential information security threats and attacks.
  • Facilitating the secure sharing of information, both internally and externally.
  • Providing organisations with a framework for complying with legal, contractual, and other requirements.
  • Offering your customers and stakeholders with the confidence that their information is well managed.
  • Assisting with compliance with other regulations (e.g., Sarbanes Oxley Act, Service Organization Control SOC 1 – Type 1 and 2, and SOC 2 – Type 1 and 2).
  • Providing your organisation with a competitive advantage over your competitors through effective security control and recognition of certification.
  • Delivering internal assurance of security by a trusted and accredited external ISO 27001 consulting or certification body.
  • Enhancing customer satisfaction that improves client retention.
  • Managing and minimising your exposure to risk.
  • Building a culture of information security within your organisation.
  • Protecting company assets from information security and cyber attacks.
  • Reducing cybersecurity insurance premiums.
  • Creating assurance and trust amongst relevant interested parties on reducing the risk of a cyber data breach.
How do I implement ISO/IEC 27001:2022 in an organisation?

WWISE has a range of professional consultants, engineers, and registered auditors to assist in implementing and maintaining your ISO management system. Our industry expertise includes services, telecommunication, manufacturing, construction, engineering services, fast-moving consumer goods, mining, power generation, state-owned companies, and government-run organisations. Each of our consultants take the time to truly understand the processes of your organisation, which will enable them to implement ISO requirements accordingly and effectively. Hiring a consultant and the time spent to implement your ISO management system will pay off in the long run.

WWISE takes a 4-Phase Approach:

  • Phase 1: Gap Analysis Audit and Information Gathering
  • Phase 2: ISO Documentation, Risk Assessment, and Process Mapping
  • Phase 3: Implementation and Training
  • Phase 4: Certification

At WWISE we provide a fully inclusive solution that includes full turnkey, awareness training, classroom and online training, and mentorship. As a consulting firm, we do not provide certification services. However, we will guide you through the certification process and ensure that your business becomes certified.

Why Choose WWISE to Assist your Organisation:
Certification Process:

An organisation can get certified to a requirement standard. You can implement the standard and get certified by a third-party.

Click here to view certification process